yx_ht.exe

602游戏

Publisher:
602游戏

Version:
5.8.8.9

MD5:
142bc1c8c1ad94e1cbee79f3a3853be8

SHA-1:
dbdf771a7c438306a973a66a002ff4a3f9b9a07e

SHA-256:
4b3ba5d080282b0e1df3186d5d8458a31f1a6b2756d6c893eb8fe23596abe04b

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 3:24:31 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.YouXun
4.0.3.1619

ESET NOD32
Win32/RiskWare.YouXun.B application
7.0.302.0

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16107

File size:
1.8 MB (1,881,600 bytes)

Product version:
5.8.8.9

Copyright:
Copyright (C) 2014-2015

Original file name:
ql.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\yx_ht.exe

File PE Metadata
Compilation timestamp:
12/16/2015 4:07:18 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:TbWkaC3t8RoaEFMC2ACmdteuz7b9drDNlxAS5AS:sC3mCa6kuzHNlxAS5AS

Entry address:
0x46DCD

Entry point:
E8, D7, 68, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, F0, C6, 47, 00, 75, 02, F3, C3, E9, 59, 69, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, D4, 2B, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 3E, 0A, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, AF, 2B, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, D6, 0F, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 20, 56, 33...
 
[+]

Entropy:
7.3185

Code size:
388 KB (397,312 bytes)

The file yx_ht.exe has been seen being distributed by the following URL.

Scan yx_ht.exe - Powered by Reason Core Security